Privacy Policy
Updated October 7, 2026
Account and generation data
Google sign-in and Supabase provide account authentication. We store account identifiers, supplied character and scene inputs, generated results, and generation status. Inputs needed to generate text are sent to the configured AI provider through OpenRouter. Avoid submitting sensitive personal information.
Sparks and payments
We store credit batches, reservations, expiry dates, provider order and payment identifiers, and subscription or refund status to deliver purchases and reconcile balances. Payment providers process checkout details; Margo does not collect full card numbers.
Feedback
We store your message, category, optional reply email, page path without query parameters or fragments, optional generator context, request identifier and handling status. A one-way network-address digest limits repeated submissions; raw network addresses are not stored in the feedback table. Feedback is private to authorized administrators.
Cookies, preferences and sharing
An anonymous session cookie links trial activity to the same browser. Local storage remembers your selected language; session storage holds pending generation identifiers and input digests for retries, without the input text. Public share links expose the selected snapshot to anyone who can access the link. Do not include confidential content.
Access, retention and contact
Operational records are retained to provide saved results, handle feedback and reconcile payments. No fixed deletion period is promised here. Request account access, correction or deletion through support@headcanon.top; records needed for unresolved transactions or legal obligations may need to be retained. Hosting, authentication, AI and payment providers process data required for their services.